CVE-2013-5035

Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
htmlcleaner_projecthtmlcleaner
𝑥
≤ 2.5
htmlcleaner_projecthtmlcleaner
0.8
htmlcleaner_projecthtmlcleaner
0.9
htmlcleaner_projecthtmlcleaner
1.0
htmlcleaner_projecthtmlcleaner
1.0.5
htmlcleaner_projecthtmlcleaner
1.1
htmlcleaner_projecthtmlcleaner
1.2
htmlcleaner_projecthtmlcleaner
1.3
htmlcleaner_projecthtmlcleaner
1.4
htmlcleaner_projecthtmlcleaner
1.5
htmlcleaner_projecthtmlcleaner
1.6
htmlcleaner_projecthtmlcleaner
1.12
htmlcleaner_projecthtmlcleaner
1.13
htmlcleaner_projecthtmlcleaner
1.55
htmlcleaner_projecthtmlcleaner
2.0
htmlcleaner_projecthtmlcleaner
2.1
htmlcleaner_projecthtmlcleaner
2.2
htmlcleaner_projecthtmlcleaner
2.2.1
htmlcleaner_projecthtmlcleaner
2.4
open-xchangeopen-xchange_appsuite
7.2.2
𝑥
= Vulnerable software versions